Hacker News new | ask | show | jobs
by grinich 4215 days ago
Just to be a bit more clear-- the difference here is with device provisioning using Mobile Device Management (MDM) services, not necessarily the default OS apps.

The user enrollment process doesn't necessarily require giving permissions beyond mail/contacts/calendar access. But many organizations take advantage of the opportunity to use pre-baked profiles which restrict behaviors, auto-configure VPN with client certs, activate features like remote wipe, etc.

We dealt with a lot of this when building the ActiveSync module for the Inbox[1] sync engine, which works with all Exchange servers and offers a modern REST API. (ie: like Twilio/Stripe for email)

https://www.inboxapp.com/

[1] Google stole our name last month. :(